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NOTE FOR: DCI 


I think that this is a useful report, 
although I have some problems with it. I have 
asked Jack Blake to send copies to the Deputy nw“ 


Directors for comment. STATINTL 


ILLEGIB 


Attachment: 
Report of the Security 
Review Task Force 
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Deputy Director for 
National Foreign Assessment 
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DDA 78-340 //y 


Attached is for your review and 


comment te the DCI via DDCI and DDA. 


John 7 en Deputy Director for 
STATINTL Administration, 7D 24 Has, 
| 


A Dec 78 


Distribution: 
0/DDA:kmg (4 Dec 78) 
Orig RS - DD/NFA w/cy 13 of Att (by hand on 12/4/78) 
Orig RS - DDO w/cy 74 of Att (by hand on 12/5/78) 
Orig RS - DDS&T w/cy 15 of Att (by hand on 12/5/78) 
Orig RS - DCI Admin (AO/DCI) w/cy 16 of Att (by hand on 12/5/78) 
- DDA Subj w/cy 6 of Att 

] - DDA Chrono w/o Att 

1} - JFB Chrono w/o Att 
Att: "A Security Review of the Central Intelligence Agency"--Nov 78 
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9 November 1978 


MEMORANDEM FOR: Deputy Director of Central Intelligence 


VIA: Acting Deputy Director for Administration 
FROM: Robert W. Gambino 

Director of Security 
SUBJECT: Report of the Security Review Task Force 
REFERENCES: a. Memo for DDA from DDCI dtd 18 Aug 1978, 


subject: Request for a Security Review 
and Assessment 


b. Memo for DDCI from DDA, dtd 31 Aug 1978, 
subject: Security Review - Interim Report 


1. Forwarded herewith is the Final Report of the Security 
Review Task Force which was established pursuant to Reference a. 
As indicated in the Interim Report (Reference b), the Task 
Force addressed itself to three topical areas: personnel 
security, physical security, and information control. Because 
of the limitation of time the report is not. exhaustive, or 
totally definitive, especially with regard to resource alloca- 
tion. Additional planning effort will be necessary to implement 
the substantive recommendations contained in this report. 


2. This summary does not include a number of recommenda- 
tions contained in working drafts which are less significant to 
the overall Agency security posture. Those which can be imple- 
mented within the present resource capability of the Office of 
Security have been or are being implemented. However, the Office 
of Security is not able to absorb additional programs which are 
manpower intensive. The core functions of this Office are being 
effectively accomplished today only because of many hours of 
voluntary uncompensated professional overtime. The time has 
come for bold action in terms of commitment of resources if the 
Agency is to significantly improve its security program. 
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3. One of the concerns expressed by the Senate Select 
Committee on Intelligence, the question of whether new 
employees should immediately be given access to highly sensi- 
tive material, was not addressed in detail by the Task Force. 
Its inquiries, however, indicated that it would be counter- 
productive for this Agency, with its highly selective per- 
sonnel, security and medical screening process, to limit new 
employees to nonsensitive and, consequently, nonproductive 
positions to further assess their security consciousness. [In 
the specific case of the Operations Center, Dr. Sayre Stevens 
has indicated that he will personally insure that a careful 
review will be made of the personnel policies which involve 
the staffing of the Operations Center and that all alternatives 
will be explored prior to permitting vacancies to be filled 
by individuals recruited directly from outside the Agency. 


4, There is another area of interest in connection with 

a recent case which the Task Force did not pursue, i.e., improve- 

ments in lie detection and behavioral predictability. ORD has 

an ongoing research program in these vital fields in coordination 
25X1A with Office of Security and the Directorate of Operations. The 

ORD effort is funded for FY 1979 at the level. 

Unfortunately, 1980 funds have been cut to The Chief, 
25X1A SE Division, Chief, CI Staff, and myself a y interested 
in pursuing these objectives and are hopeful that current efforts, 

which are.of an exploratory nature, can be refined to a point 

where they can be used in our vetting and selective processes 

in the near future. Obviously, additional funding for FY 1980 

and out years will be required.. 


5. Technical assistance to document control is still 
being examined. The R&D Working Group of the Security Committee, 
in coordination with Agency components, is reviewing the possi- 
bility of diode technology, special papers and inks, and a 
number of other technical applications but, to date, these 
efforts have not been too encouraging. 


6. The Area Security Officer concept (Recommendations 1 
and 2), as the report points out, was adopted from the Office 
of Security, CIA, by NSA, where it is flourishing as a corner- 
stone of that agency's security program. At CIA, unfortunately, 
we have seen the concept subordinated to parochial staffing/ 
budgetary interests to the point that it is virtually nonexistent. 
I fully endorse the revitalization of this program but it is one 
which has measurable impact on resources, both of the Office of 
Security and the components concerned, and, consequently, is a 
matter properly for your executive decision. 
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?. I also endorse Recommendation 3 regarding security 
education and training; Recommendation 4 regarding reinvesti- 
gation and repolygraph at the end of a new employee's trial 
period; and Recommendation 5 which would amplify the scope of 
secret-level contractor clearance investigations. It is 
important to upgrade the requirements for access to secret 
material in anticipation of more conservative Classification 
actions resulting from implementation of Executive Order 12065. 


8 Many of the recommendations deal with improved docu- 


mene control, the necessity of which is clearly established in 
STATINTL the report. The ST >=: as well as implemen- 
tation of Executive Urder » Should help reduce over- 


compartmentation and overclassification, both of which are root 
causes of the document control problems highlighted by the Task 
Force. However, there is major impact on resources, functions, 
and even organizational structure inherent in those recommenda- 
tions which must be addressed carefully. I feel that Recommenda- 
tions 15, 21, and 22 should be approved in any event because 
implementation will bring about greater document control without 
dramatic increase in current resources. 


9. I appreciate the trust implied in the fact that this 
study .ef security procedures and security-related matters was 
levied on the Office of Security in expectation that a no-holds- 
barred review would be conducted. I levied this assignment on 
the Task Force in the same spirit. Not everything in the report 
is the way I would like to have seen it come out but I think 
that the spirit of candor and self-criticism will ultimately pay 
dividends in necessary improvements in Agency security pro- 
cedures. 


25X1A 


obert W. GamBino 
Attachments 
Distribution: 
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1 - DCI 
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Approved For Release 2001/08/02 : ciaSp bat hol 42R000600080007-4 


Approved For Release 2001/08/02 : CIA-RDP81-00142R000600080007-4 


TAB 


Approved For Release 2001/08/02 : CIA-RDP81-00142R000600080007-4 


. Poe 


7 Les? eee ere a { ie 
{ 
i 


- Approved F For Release 2004/08/02 : CIA-RDP81-00142R000600080907-4. ae 
78- Ee 


l nae dta tion Rerssee 


a eonel babes 


LJReOQLB/2 


18 August 1978 


MEMORANDUM FOR: Deputy Director for Administration 
FROM : Deputy Director of Central Intelligence 


SUBJECT : The Kampites Case - A Request for a Security Review 
and Assessment 


1. It is obvious from the events of the past 48 hours regarding 
the Kampiles case that it is necessary to commence immediately a total 
and comprehensive review of all personnel security, physical security, 
and procedure security activities of this Agency. This review should 
focus on the policy basis of our entire security program as well as the 
procedures that flow from these policies. I would expect this review 
to lead to the most comprehensive recommendations seen to be necessary 
to preclude any such happening again in our future. 


2. I hereby task you to initiate such a comprehensive security 
- review giving it your highest priority and personal attention. 


3. I will expect your first interim report, after scoping the 
problem, to be in my hands no later than 1 September 1978. 


25X1A 
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HENORANDGA FOR: Deputy Director of Central Intelligence 


PROM: John F. Blake 

Deputy Director for Administration 
SUBJECT: Security Review - Interim Report 
REPERENCE: Meaorandum for DOA from DOCT, dated 


18 August 1978, Subject: A Request 
for a Security Review and Assessment 


1. Action Requested: None; for information only. 


2. Background: Following the mid-August 1973 revelation 
that a formar Agency employee had sold classified infornation 
to the Soviets, you directed a comorehensive review of the 
Agency's sacurity policies and procedures and called for an 
interim report Dy 1 September 1973. Subsequently, the Director 
has expanded the scope of the interim report to include: 

{a} a cataloguing of specific improveménts in the Agency's 
Security program realized since his appointment end by his 
initiatives; and (b) a listing of proceduras currently beins 
initiated to further improve the security of classified in ®or- 
mation. Pursuant to those directions, this interin report is 
subsaittad. 


- 3. Staff Position: In April 1977, following the reve- 
lations ox the Moors and Boyce/Lee espionage cases, a coupre- 
hensive impact study was completed by the Office of Security. 

AS a consequence, the Director caused several sacurity initiatives 
and gave the necessary impetus to others which have been success- 
fully implemented to the enhancement of Agency and Intellicence 
Community security. Agency programs successfully inplemented 
ineciude: 


a. <A rigorous staff personnel security 
reinvestigation program 
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c. Enhancement of appraisal criteria in 
Industrial Security Approvals. 


a. Initiation of the Industrial Contractor 
Polygraph Program. 


e. Increased snot checks of briefcases, 
packages and parcels at all Agency facilities in 
the Washington Metropolitan araa. 

#. Initistion of a program of unannounced 
curity audits of Agency contractor facilities. 


g- Initiation of research to enhance security 
movement of classified information via tamper-resistant 
security containers and to preclude unauthorized 
reproduction of documents via use of special paper, 
Special inks and other techniques. 


h. <A personal interest in and involvement by 
the Dirsctor and sanior Agency managers in the 


-adjudication’ and penalty assessuant procedures 


involving Agency employees who have violated secu- 
rity regulations. 


Programs initiated by thea director to tightens the sacu- 


of the Inteiligence Community have inctudad: 


a. The strengthening of the Director of Central 
Intelligences Security Committees as a focal point for 
Teporting and tracking unauthorized disclosures and 
for raising security consciousness in the Community. 


b. Maintaining a freeze since 1 June 1977 on the 
total number of sensitive compartmentad clearances 
throughout the Community. 


<. Initiation of a programa to revalidate secur 
clearancas by effecting zero-based reviews in Intel 
genca Community and contractor vacilities. 


ity 
Li- 


d. Directing contracting and legal suthorities to 
strengthen tha security provisions of contracts becween 
connereial firms and Intelligence organizations. 


Ci ool 
us 


P81 - Baer 


Phot! Ce Yeu u 


9no7-4 
“af 


. RETuR any = boehidl Ga iy 
" Approved For Release 2004/08/02 : CIA-RDP81-00142R000600080007-4 


I can assure you the Director of Security has and 
is continuing to dedicate all available personnel resouress, 
as well as his personal attention, to the programs outliaed 
above. 


In accordance with your specific request of 18 Augu 


‘ 
1978, a comprehensive review of the Agency's security pollicis 
and procedures has commenced. 


- 
- 
~ 
xs 


During the week of 21 August the organization and 
staffing of a Sacurity Review Task Fores was undertaken. 
Ths Task Force will approach the review in three segments. 
Each segment staff will function under the leadership of a 
senior experienced officer. The segments will address, 
separately, Personnel Security, Physical Sacurity, and Infor- 
mation Control and Protection. The magnitude of the task 
is awesome, and the Director of Security estimates a cosore- 
hensive review will require a minimus -of sixty {66) days. 


The Personnel Security Segment of the Task Force 
intends to inyestigate all periods of an emplayee's carear 
from preenployment processing through post-eaployment counselins. 
tt is their intent to survey personnel recruitment and assiga- 
ment policies and procedures which are quite varied from 
directorats to directorate and froa office to office. Although 
the emphasis in this segment will be on staff employees, the 
Task Fores will also survey the several other types of individuats 
who ara utilized by the Agency. The entire security clearance 
process from pre-field investigation to final adjudication will 
ts reviewed, as will the vast number of policies and procedures 
that pertain during the employment phase. 


The employment phase topics include security indectrit- 
nation/reindoctrination; marriage, including marriaze to an 
alien; outside activities; handling of misconduct incidents: 
counterintelligence review of high risk personnel and organiza- 
tional units; the reinvestigation program; security and 
suitability reviews for overseas candidates; Agency manazeaen~ 
responsibilities; and the Personnel Evaluation Board. Finally, 
the Agency’s out-processing policies and procedures as weli as 
current policies relative to post-enployment counseling will > 
addressad under this segment. 


Tne Task Force will exclude froa its review the 
i i security policy procedures and practices concernins 
individuals who are utilized by the Directorate of 
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Qperations in an operational and informational capacity g:ch 
as- double agents and clandestine sources. That policy is 2 
DDO rasponsibility. 


The Physical Security Segment has an enormous task 
at hand. This segment will Limit the scopa of their review 
by concentrating primarily upon the physical security prograa 
as it is pursued within the Headquarters Building. The sub- 
Stantive areas which constitute the physical security program 
of the Agency can be examined in relation to operations within 
the Headquarters Building within a reasonable tine frama@pinty- 


Essentially our physical security policies and pracs- 
dures at Headquarters have bean adopted in our 
overseas facilities, and available rasource and time constraints 


Pod 


dictate that but cursory be given to the nature and 
scope of ths cvers os SiMMMMMRI Zaciiities 7 
curing the survey. arly, this raview wi e SVECLsicasty 


cover the physical security aspects of our industrial security 
program because that subject has bean thoroughly reviewed during 
the past year. And finally, we consider the tectmical threat 

as Well as the measures which have been implemented ta counter 
this threat as beyond the scope of this review. 


. The Physical Security Sagment of the Task Force will 
address thoroughly the policias and procedures partaining to: 
perimeter security; building security; access controls for 
all types of people from staff employees to vendors; badges: 
entry and exit inspection procedures; internal personnel control: 
Storage of classified information; the Agency's guard progran: 
intrusion datection systems and other monitoring eauipment; 
after hours security procedures and the security violation pro- 
groom. 


The Information Control and Protection Segment pro- 
poses to review the application by CIA of directives and 
regulations governing the production, marking, ciassificarion, 
reproduction, transmission, inventory and overall control of 
classified information. These will be reviewed for current 
applicability to determina whether rules are being observad, 
and, if so, whether a significant measure of control results 
from their cbservance. The scope of this Segment will includs 
an inquiry into the level and efficiency of employee training. 

i document control procedures; an examination of the posidility 
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of handling information at Lower levels of classification 

or compartmentation; exploration of methods to reduce the 
ancunt of classified material retained in the Agency; inquiry 
into the efficacy of current ADP and microform information 
control, and the stata of pre-planning for future information 
tachknolagy requirements. Finally, we intend to examina alcer- 
native ways of controlling accountability for classified 
materials, including automated tachniquas. 


Obviously, to conduct the survey effectively, the 
Task Fores will require the complete cooperation of the 
Agancy’s population. For example, to meaningfully describe 
Current procadures under the Personnel Security Segment is 
going to require close cooperation with several offices, 
especially the Offices of Personnel and the Office of Medical 
Services. Furthermore, several offices throughout the Agency 
are involved in the recruitment of personnel, and their 
cooperation will also ba necessary. Consequently, it is recon- 
mended that you solicit the cooperation of all directorates 
with the members of the Task Forca, 


The Task Force will approach its task by extensive 
documentary reviews, personal interviews both within and 
external to the Agency, and by discussion within the Task 
Fores which will lead to a series of recommendations concerning 
the Agency's security program. The Task Force members have 
been axhorted to approach the task, particularly the reconmen- 
dations, with absolute objectivity and personai integrity, as 
we view the review as an opportunity to assure our security 
policies and procedures are right for the time. 


Wa envision a final report to be submitted to you 
by 3 November 1973. We expect that report to be in four 
parts: {a) a description of current policies and procedures; 
(5) analysis of current policies and procedures; (c) conciusiozs; 
and (d) recommendations. 


The current review will be thorough. ‘We anticipate 
specific recommendations pertaining to the restatement of th 
basic principle that Security is a command responsibility 
within the Agency, i.e., the responsibility of each manager 
and supervisor. Furthermore, we expect to relate the apparens 
deterioration in security discipline in the operating conponrsats 
to the reduction of professional security positions in those 
components over the nast decade; in ten years the number of 
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aresrists assignad to other TO's has dropoed fro. 
of those positions were located over- 
STATINTL g0a3 and were at Headquarters. Thess issues 
caquire orderly analysis before rocomnending specific changes. 
STATINTL 


Neyartheless, the urgency of the present situarion 
calls for the implementation of innroved procedures and ney 
initiatives prior to complation of tha formal review. Towards 
that ond ths following actions hava been taken: 


fa) Commencing 11 September 1978 the briefcase, 
package inspection progrem will be expanded and con- 
ducted by the Faderal Protective Officers on a routine 
basis seven days a weak and twenty-four hours a day. 


{>} Commencing immediately, systematic counter- 
intelligence procedures will be established by the 
Offices of Security to investigats employee accesses 
to secure areas outside of normal duty hours and to 
review the pattern of employee after-hours accesses 
to Headquarters area buildings. 


(c} The Office of Security currently has ordared 
active studies into two methods of controlling dcocumant 
reproduction. One cancept involves the nodification 
of raproduction equipmant to house a badge reader 
which would maintain accountability for all copies 
laada 22 least to the extent of maintaining an audit 
trail of an individual eavloyge's use of the ecenipmsnc. 
The other concapt involves davalopment of a paper or 
print process which is not capiable. 


{d) The Danuty Directors of the Agency are being 
directed, immediately, to establish positive, account- 
able document controls for particularly sensitive 
materials under their cognizancea. 


(2) Arrangements are being finalized for the 
Office of Security to conduct a series of briefings 
of senior staffs throughout the Agency. The driefings 
will conprehensively review security problems discovered 
during the past several months through the reinvesti- 
gation program, briefcase inspection program, etc., 
and will reemphasize the command and managerial respon- ~ 
sibility in implementing sound security practices. 
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(f) The Office of Security is reminding Agency 


managers that personnel are available as speake 


panelists, consultants, etc, to assist command chan- 
nels in the security education and reindoctrination 
of small employee groups. As you know, the Office 

of Security recently completed a formal reindoctri- 


nation of the Agency population in a number of 
presentations to larse audiences. 


4. Conclusion: In accordance with the reference, I 
assure you that the Security Review is receiving the highest 
priority and my personal attention. The Scope of the task, 
ia my opinion, fully justifies a 3 November 1978 final reporting 


date. 
“peftonin F Blake 
John F. Blake 
Distribution: | 
Orig - Addresse 
2 - DDA cero 
1 ER 
STATINTL 
ORIGINATOR: 


| a . ° a LnNO 


Director of Security 
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25 August 1978 


MEMORANDUM FOR: Director of Central inteltigence/77) 


FROM: John F. Blake 
Deputy Director for Administration 


« 
i 


Stan: 


1s Mindful. of...the- Kamptl es case: ree and 25X1A 
your strong desire that we be more aggressive in the discharge 


of our security responsibilities, I am forwarding to you for your 
review the attached binder. We would have preferred to wait a 
little longer and presented you with a finished plan. IJ am 


from OGC on 27 June 1978. Secondly, you have asked that we com- ff 
mence a “selective spot check" in the buildings as of Mondaye-" — A, 2 ag Ps 
morning. As I have reviewed this plan, the target date for aye ae 
implementation of which is 1 September, I am somewhat persuaded 7 4 

we would be better off to wait the axtra week involved and have Ag 
a capability to commence operation capac studied fashiar. ay y 


2. T*would- appreciate-yourccoments’ tf you agree with this pars 
..appraach:which..the. Office of. Security: has< been working on and; 
-addttionatlys Tf we: can: get:intor this. new. mode: or} September: 


STATINTL 


Att i 
Distribution: 
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1 - DDA w/o att 
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18 August 1978 


B-390 | 


MEMORANDUM FOR: Deputy Director for Administration 
FROM : Deputy Director of Central Intelligence 


SUBJECT : The Kampiles Case - A Request for a Security Review 
and Assessment 


}. It is obvious from the events of the past 48 hours regarding 
the Kampiles case that it is necessary to commence immediately a total 
and comprehensive review of all personnel security, physical security, 
and procedure security activities of this Agency. This review should 
focus on the policy basis of our entire security program as well as the 
procedures that flow from these policies. I would expect this review 
to lead to the most comprehensive recommendations seen to be necessary 
to preclude any such happening again in our future. 


2. I hereby task you to initiate such a comprchensive security 
review giving it your highest priority and personal attention. 


3 Iwill expect your first interim report, after scoping the 
problem, to be in my hands no tate 


25X1A 
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8 August 1978 
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Security Task Force Report 


John F. Blake = 7 
Deputy Director for Administration 


ea Saleen non eee COMMENTS (Number each comment to show from whom 


fo whom. Draw a line across column after each comment.) 


OFFICER'S 
INITIALS 


FORWARDED 


RECEIVED 


Director of Security Bob, 
4 E 60 
2. I am not sure whether you had 
seen the attached note. I am 
STATIN]L sure moreca romeo those who 
3. worked on the Task Force would 
be interested in the Director's 
comment. 
4, ‘ . 
I have received the NFAC and DDO 
responses and will hold them 
5. : until I receive responses from . 
au DDS§T and O/DCI. These will then 
be forwarded to you so that you 
6. may pull the comments together 
in some meaningful form to pass 
on to the DDCI, 
7. ei ae 
STATINT 
8. 
_ John F, Blake 
9 ‘ Att 
10. ‘ ’ EO/DDA cn OS Tea re 
| 
Distribution: 
Te 4 | Orig PRS - D/Sec (w/att) . 
| -it- DDA Subj (w/att) 
it 1 - DDA Chrono (w/att) 
12. ) 1 - RFZ Chrono (w/att) 
‘goo ae “Att: Copy of Note from DDCI to DCI dtd 4 Dec 
78 with handwritten note by DCI (ER 78-9918/15) 
14, . 
15. 
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